Ransomware has been weaponized by cyber extortionists and malicious states, posing a potentially lethal risk to companies that are victimized. The latest strains of ransomware target everything, including online backup, making even partial recovery a long and costly exercise. New versions of ransomware such as Ryuk, Maze, Sodinokibi, Mailto (aka Netwalker), Phobos, Conti and Egregor have emerged, replacing Locky, Cerber, and CryptoWall in prominence, sophistication, and destructiveness.
90% of ransomware breaches come from innocent-looking emails with dangerous links or attachments, and many are "zero-day" strains that can escape detection by traditional signature-based antivirus (AV) filters. While user training and up-front identification are critical to defend against ransomware, best practices dictate that you assume some malware will inevitably succeed and that you put in place a solid backup solution that enables you to recover quickly with little if any damage.
Progent's ProSight Ransomware Vulnerability Report is a low-cost service built around a remote interview with a Progent security expert skilled in ransomware protection and repair. In the course of this assessment Progent will work with your The Woodlands network management staff to gather pertinent information about your security posture and backup processes. Progent will use this information to create a Basic Security and Best Practices Assessment documenting how to adhere to best practices for implementing and managing your cybersecurity and backup systems to prevent or recover from a crypto-ransomware attack.
Progent's Basic Security and Best Practices Assessment highlights key areas related to ransomware prevention and restoration recovery. The review covers:
Security
About Ransomware
Ransomware is a variety of malicious software that encrypts or deletes files so they are unusable or are publicized. Crypto-ransomware often locks the victim's computer. To avoid the carnage, the target is asked to pay a certain amount of money (the ransom), typically via a crypto currency such as Bitcoin, within a short period of time. It is never certain that delivering the extortion price will restore the lost files or prevent its exposure to the public. Files can be encrypted or deleted throughout a network depending on the target's write permissions, and you cannot solve the strong encryption technologies used on the hostage files. A typical ransomware attack vector is spoofed email, in which the target is tricked into interacting with by means of a social engineering exploit known as spear phishing. This makes the email to look as though it came from a trusted sender. Another popular attack vector is a poorly protected RDP port.
CryptoLocker ushered in the new age of crypto-ransomware in 2013, and the damage caused by different strains of ransomware is said to be billions of dollars per year, roughly doubling every other year. Famous examples include Locky, and Petya. Current headline threats like Ryuk, DoppelPaymer and Spora are more elaborate and have wreaked more damage than older versions. Even if your backup/recovery processes allow you to restore your ransomed data, you can still be threatened by exfiltration, where ransomed documents are made public (known as "doxxing"). Because additional versions of ransomware are launched every day, there is no certainty that conventional signature-matching anti-virus tools will block a new malware. If an attack does appear in an email, it is important that your end users have learned to be aware of phishing tricks. Your ultimate defense is a solid scheme for performing and retaining offsite backups plus the use of reliable recovery platforms.
Contact Progent About the ProSight Crypto-Ransomware Vulnerability Checkup in The Woodlands
For pricing information and to learn more about how Progent's ProSight Crypto-Ransomware Preparedness Consultation can bolster your defense against crypto-ransomware in The Woodlands, call Progent at